mirror of
https://github.com/kernelkit/infix.git
synced 2026-07-30 20:43:02 +02:00
factory-config: Add default NACM deny rule for reading password hash
This fix #499
This commit is contained in:
@@ -1,5 +1,6 @@
|
|||||||
{
|
{
|
||||||
"ietf-netconf-acm:nacm": {
|
"ietf-netconf-acm:nacm": {
|
||||||
|
"enable-nacm": true,
|
||||||
"groups": {
|
"groups": {
|
||||||
"group": [
|
"group": [
|
||||||
{
|
{
|
||||||
@@ -25,6 +26,19 @@
|
|||||||
"comment": "Allow 'admin' group complete access to all operations and data."
|
"comment": "Allow 'admin' group complete access to all operations and data."
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"name": "default-deny-all",
|
||||||
|
"group": ["*"],
|
||||||
|
"rule": [
|
||||||
|
{
|
||||||
|
"name": "deny-password-read",
|
||||||
|
"module-name": "ietf-system",
|
||||||
|
"path": "/ietf-system:system/authentication/user/password",
|
||||||
|
"access-operations": "*",
|
||||||
|
"action": "deny"
|
||||||
|
}
|
||||||
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user